Europe talks about artificial intelligence in the language of ambition. There are sovereignty strategies, competitiveness agendas and billions earmarked for compute capacity. Yet beneath the rhetoric sits a dependency that few boards examine closely. The strategic question is not how much computing power Europe builds. It is the question of whose legal jurisdiction that power ultimately answers to.
For most European companies running AI workloads today, the honest answer is uncomfortable. The compute lives, legally if not physically, somewhere else. The hardware may hum away in a European data centre, but the entity that controls it, and the legal system that entity answers to, often sits an ocean away.
Why “where the compute lives” is now a board-level question
For a decade, the location of computing infrastructure was an operational detail. You picked a provider, chose a region from a dropdown menu, and moved on. AI has changed that calculus. Training and serving large models concentrates enormous value, sensitive data and competitive advantage in a single layer of infrastructure. That makes the legal status of the layer a strategic concern rather than a procurement footnote.
Join The European Business Briefing
New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.
SubscribeEuropean regulation has caught up faster than corporate habits. Data residency obligations, the NIS2 directive on network and information security, and a broader push for digital sovereignty all point in the same direction. Where data is processed, and under whose laws, has become a question of compliance and corporate risk. Boards that once delegated this to the IT function now find it landing on the risk register.
The change is partly geopolitical. A few years ago, the assumption that transatlantic data arrangements were stable enough to build on went largely unquestioned. That assumption is harder to make today. Trade tensions, shifting enforcement priorities and the general fragility of cross-border legal frameworks have all made jurisdiction feel less like a technicality and more like a variable that can move against you.
What dependence on US hyperscalers actually exposes you to
The dominant cloud platforms are operated by US-headquartered companies. That single fact carries legal weight regardless of where the servers physically sit. Under the US CLOUD Act, American authorities can compel those providers to hand over data they control, even when it is stored in a data centre on European soil. A server in Frankfurt does not place a US company’s data beyond the reach of US law.
This is the distinction that gets lost in vendor marketing. Selecting an “EU region” on a US hyperscaler tells you where the machines are. It does not change whose jurisdiction governs the data on them. For a regulated bank, a defence supplier or a health provider, that gap between physical location and legal control is precisely where the risk lives.
Concentration is the second exposure. When a handful of providers host most of Europe’s AI workloads, pricing power and lock-in follow. Egress fees, the charges levied to move your own data out of a platform, quietly tax any attempt to leave. The result is an infrastructure relationship that is expensive to enter and even more expensive to exit. Over a multi-year AI programme, those switching costs can quietly become the single largest line item nobody budgeted for.
None of this requires bad faith on the part of the providers. It is simply the structure of the market. A dependency built on convenience during the experimental phase of AI becomes a strategic vulnerability once those systems are running the business.
Can Europe realistically run frontier AI on its own terms?
The honest constraint is not ambition or talent. It is power and physical capacity. Advanced AI clusters draw extraordinary amounts of electricity, and the bottleneck for European AI is increasingly the grid rather than the chip order. As this publication has noted, the sector is less short of capital than it is short of power. Frontier compute now goes where energy is available, affordable and reasonably clean.
That reframes the sovereignty debate in useful ways. Former European Central Bank President, Mario Draghi’s report on European competitiveness argued that the continent cannot afford to treat strategic infrastructure as something to be rented indefinitely from others. The full competitiveness report sets out the case in detail, and AI compute is one of its clearest examples.
Encouragingly, an alternative is taking shape A handful of newer operators, including at least one sovereign AI cloud provider in Southeastern Europe, now run current-generation, Blackwell-class GPU capacity outside US CLOUD Act jurisdiction, on European soil and under European data-protection rules. Southeastern Europe is a credible home for this. The region offers grid capacity, competitive energy and operating costs, and an EU-aligned regulatory footing, without the land and power constraints that now throttle the established Western European hubs.
None of this means abandoning the hyperscalers. For many workloads they remain the right choice. The point is that European firms now have a genuine option for the workloads where jurisdiction, cost predictability and control actually matter.
What European decision-makers should actually ask
Sovereignty becomes meaningful only when it turns into a procurement criterion. For boards and technology leaders evaluating where to run AI, a short set of questions does most of the work.
First, under whose jurisdiction does this provider operate, and could a foreign legal order compel access to our data? Second, what are the egress terms, and what would it actually cost to move our models and data elsewhere in eighteen months? Third, is current-generation GPU capacity contractually guaranteed, or are we joining a waiting list? Fourth, does the provider’s compliance posture match the regimes we answer to, from GDPR to sector-specific rules?
These are not technical questions. They are governance questions, and they belong in the boardroom rather than buried in a vendor comparison spreadsheet. A chief executive does not need to understand GPU architecture to ask whose courts can reach the company’s most sensitive data. That is a question of corporate control, and it is answerable in plain language.
The strategic stakes
Europe’s AI debate has focused on models, talent and funding. The quieter and arguably more decisive variable is location: not the postcode of the data centre, but the legal order that governs what happens inside it. As AI moves from experiment to core infrastructure, where the compute lives becomes a question of strategic autonomy. The firms that ask it early will be the ones still in control of their own systems when it matters.



































